本文へ移動
cccskills
無料GitHub で公開

pinned-tag

Manage pinned tags and commit SHAs for GitHub Actions security, resolving mutable tags to immutable commit references. Use when the task involves `Unpinned tag for a non-immutable Action`, `pin GitHub Action to commit SHA`, `resolve git tag to SHA`, or `GitHub Actions security hardening`.

インストール方法を見る

含まれるファイル(1)

  • SKILL.md3.6 KB

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Pinned Tag Management Skill

Skill for managing "pinned tags" and commit SHAs, primarily for GitHub Actions security.

Overview

This skill helps locate and validate tags in remote repositories using git ls-remote --tags, resolving the specific commit SHA for a tag (including annotated tags), and providing patches to pin dependencies. It specifically targets GitHub Actions security best practices by encouraging the use of full commit SHAs instead of mutable tags.

When to Use

  • You need to fix "Unpinned tag for a non-immutable Action in workflow" security alerts.
  • You want to ensure reproducibility by pinning a GitHub Action or dependency to a specific commit SHA.
  • You need to verify if a tag exists before updating a manifest or CI workflow.

Critical Patterns

  • Immutability for Actions: For GitHub Actions, always prefer the full 40-character commit SHA over a tag name. Tags are mutable and can be moved, leading to security risks or broken builds.
  • Annotated vs Lightweight Tags:
    • Annotated Tags: git ls-remote returns two entries. The one ending in ^{} is the " peeled" reference pointing directly to the commit object. ALWAYS use this one.
    • Lightweight Tags: Return only one entry, which is the commit SHA.
    • Selection Logic: When resolving, always sort the results and take the last one to ensure ^{} is preferred over the tag object SHA.
  • Verification: Always verify the resolved SHA belongs to the expected tag before applying changes.

Commands

  1. Resolve Tag to SHA (GitHub Actions Friendly):

    # Example: Resolve 'v2' tag for actions/checkout
    # This command ensures that for annotated tags, the commit SHA (peeled tag ^{}) is selected
    # by sorting and taking the last entry (where ^{} alphabetically follows the base tag).
    git ls-remote --tags https://github.com/actions/checkout.git | rg "refs/tags/v2(\^\{\})?$" | sort | tail -n 1 | awk '{print $1}'
    
  2. List all remote tags:

    git ls-remote --tags https://github.com/owner/repo.git
    
  3. Check for specific tag existence:

    git ls-remote --tags https://github.com/owner/repo.git | rg "refs/tags/v1.2.3"
    

Workflow for GitHub Actions

  1. Identify the Action: Find the uses: owner/repo@tag line in the workflow YAML.
  2. Resolve SHA: Run git ls-remote --tags https://github.com/owner/repo.git filtered by the tag.
  3. Apply Patch: Replace the tag with the SHA and add the tag name as a comment for readability.
  • Before: uses: actions/checkout@v3
  • After: uses: actions/checkout@f43a0e5ff2bd294095638e18286ca9a3d1956744 # v3

Limitations

  • Cannot access private repositories without proper credentials (SSH/Token).
  • Some actions may not use standard semver tags; always double-check the remote refs.

Commit Policy

  • This skill does NOT create commits automatically without explicit permission.
  • Suggested commit message: sec(ci): pin <action-name> to commit SHA for immutability

Resources

レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Audit and improve web accessibility following WCAG 2.1 guidelines. Use when the task involves `improve accessibility`, `a11y audit`, `WCAG compliance`, `screen reader support`, `keyboard navigation`, or `make accessible`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

astro

無料

Skill for building with the Astro web framework. Helps create Astro components and pages, configure SSR adapters, set up content collections, deploy static sites, and manage project structure and CLI commands. Use when the user needs to work with Astro, mentions .astro files, asks about static site generation (SSG), islands architecture, content collections, or deploying an Astro project.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Apply modern web development best practices for security, compatibility, and code quality. Use when the task involves `apply best practices`, `security audit`, `modernize code`, `code quality review`, or `check for vulnerabilities`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Optimize Core Web Vitals (LCP, INP, CLS) for better page experience and search ranking. Use when the task involves `improve Core Web Vitals`, `fix LCP`, `reduce CLS`, `optimize INP`, `page experience optimization`, or `fix layout shifts`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Advanced Docker containerization expert for multi-stage builds, image optimization, security hardening, and Compose orchestration. Use when the task involves `working with Dockerfile`, `docker-compose.yml`, `containerization`, `multi-stage builds`, or `optimizing Docker images`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

Create distinctive, production-grade frontend interfaces with high design quality that avoids generic AI aesthetics. Use when the task involves `build web components`, `create frontend interface`, `build web page`, `build web application`, `frontend design`, `create UI component`, or `design web interface`.

日本語の概要は準備中です。原文の説明を表示しています。

dallay/agentsync652026年10月11日 更新

dallay のスキルをすべて見る

このスキルの問題を報告する